chore(deploy): track the container + nginx deploy setup

Production hosting artifacts (D20 hosting slice), previously untracked:
- Dockerfile: node:20-bookworm image, Chromium libs for puppeteer, builds
  web + server, runs server.cjs on 5182
- docker-compose.yml: single hq service, external accurate-postgres via
  host.docker.internal, localhost-bound (host nginx terminates TLS), env_file
- deploy/nginx-hq.conf: the reverse-proxy config

No secrets — .env and data stay gitignored and out of the image (.dockerignore).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
feat/client-detail-redesign
Thomas Joise 4 days ago
parent b41625597c
commit 08e3c02ae7

@ -0,0 +1,30 @@
# SiMS HQ console — production image (D20 hosting slice).
# Runs the Express server, which also serves the built React UI and the public
# /share links, on port 5182. Postgres is EXTERNAL (the shared `accurate-postgres`
# container), reached over the host gateway — see docker-compose.yml.
FROM node:20-bookworm
# Chromium runtime libraries for puppeteer (PDF letterhead rendering).
RUN apt-get update && apt-get install -y --no-install-recommends \
ca-certificates fonts-liberation \
libnss3 libnspr4 libatk1.0-0 libatk-bridge2.0-0 libcups2 libdrm2 \
libgbm1 libxkbcommon0 libxcomposite1 libxdamage1 libxfixes3 libxrandr2 \
libpango-1.0-0 libcairo2 libasound2 libatspi2.0-0 libgtk-3-0 \
libx11-6 libxcb1 libxext6 libxi6 \
&& rm -rf /var/lib/apt/lists/*
WORKDIR /app
# Install all workspaces (also fetches puppeteer's Chromium + better-sqlite3 prebuilt
# binary for linux-x64), then build the web UI and bundle the server.
COPY . .
RUN npm install \
&& npm run build --workspace @sims/hq-web \
&& npm run build --workspace @sims/hq
ENV NODE_ENV=production
EXPOSE 5182
# Launch from the repo root: server.cjs resolves ../../hq-web/dist for the UI and
# loads better-sqlite3/puppeteer (kept external from the bundle) from ./node_modules.
CMD ["node", "apps/hq/dist/server.cjs"]

@ -0,0 +1,26 @@
# SiMS HQ console — host nginx vhost. Install as:
# sudo cp deploy/nginx-hq.conf /etc/nginx/conf.d/sims.hq.conf
# sudo nginx -t && sudo systemctl reload nginx
# Reuses the existing *.simssoftware.in wildcard cert. Proxies to the HQ container,
# which publishes on 127.0.0.1:5182. The public /share/:token links go through here too
# (intended: token-guarded, rate-limited, revocable).
server {
listen 80;
server_name hq.simssoftware.in;
return 301 https://$host$request_uri;
}
server {
listen 443 ssl;
server_name hq.simssoftware.in;
ssl_certificate /etc/ssl/sims/sims.crt;
ssl_certificate_key /etc/ssl/sims/sims.key;
location / {
proxy_pass http://127.0.0.1:5182;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}

@ -0,0 +1,19 @@
# SiMS HQ console — one service. Postgres lives in the separate, shared
# `accurate-postgres` container; HQ reaches it via host.docker.internal (that container
# publishes 5432 on the host), so nothing about accurate-postgres changes.
# Bring up: sudo docker compose up -d --build
# Logs: sudo docker logs sims-hq
# Restart: sudo docker compose restart hq
services:
hq:
build: .
image: sims-hq
container_name: sims-hq
restart: unless-stopped
env_file: apps/hq/.env
# Bind only to localhost — the host nginx terminates TLS and proxies here.
ports:
- "127.0.0.1:5182:5182"
# Lets DATABASE_URL use host.docker.internal:5432 to reach accurate-postgres.
extra_hosts:
- "host.docker.internal:host-gateway"
Loading…
Cancel
Save